Skip to main content
Zwei Männer in Business Kleidung schütteln sich die Hände Vertrauensdienste

Trust services form the foundation for secure, legally valid, and traceable digital transactions. For businesses, public administration, the public sector, and education, this goes beyond electronic signatures. Trust services also include seals, timestamps, certificates, registered delivery, identification, and preservation services.

This is precisely why they are a central building block for digital processes: they help to make the identity, integrity, and origin of electronic documents verifiable—within a shared European trust space. Practical applications range from contract processes and official notices to secure digital evidence.

Trust services are electronic services that establish trust and security in digital processes. The legal foundation is provided by the European Union’s eIDAS Regulation. It governs how electronic identities, signatures, seals, and other trust services are recognized within the European single market.

In Switzerland, the Federal Act on Certification Services in the Field of Electronic Signatures (ZertES) provides the national framework for trust services. It sets out the requirements for providers, certificates, and the legal recognition of electronic signatures and seals—similar to the eIDAS Regulation in the EU.

It is important to note: Trust services and electronic signatures are not the same. The signature is just one of several types of trust services. While an electronic signature represents the declaration of intent of a natural person, an electronic seal, for example, can confirm the origin of a document from a company or public authority.

What Types of Trust Services Are There?

The most important trust services include:

  • Electronic signatures, including the qualified electronic signature (QES)
  • Electronic seals for businesses, organizations, and public authorities
  • Electronic timestamps to securely document a point in time
  • Certificates for signatures, seals, or website authentication
  • Electronic registered delivery services for secure communication
  • Preservation services, such as for the long-term retention of qualified signatures and seals

In practice, this means: Trust services not only secure contracts, but also notices, applications, evidence, test reports, approvals, and other business-critical documents. Depending on the application, the focus may be on identity, integrity, delivery, timing, or long-term verifiability.

In Switzerland, the requirements for these services are defined in ZertES. The qualified electronic signature (QES) under ZertES is legally equivalent to a handwritten signature and is recognized for official and business transactions.

Benefits of Trust Services for Businesses and Public Administration

Trust services add value wherever digital processes require high verifiability, security, and legal reliability. For businesses, public authorities, and educational institutions, this translates into several practical benefits:

  • Legal certainty: Qualified trust services under eIDAS provide a robust foundation for electronic signatures, seals, timestamps, and digital evidence.
  • Seamless processes: Documents no longer need to be printed, manually signed, scanned, or sent by post.
  • Enhanced security: The identity, integrity, and origin of documents can be secured both technically and organizationally.
  • Improved traceability: Timestamps, certificates, and verification mechanisms make digital transactions auditable and verifiable.
  • EU-wide and pan-European recognition: Thanks to the eIDAS Regulation, qualified trust services can be used across borders within the European single market. By complying with ZertES, these services can also be extended to Switzerland.
  • Efficiency in core processes: Trust services can be integrated into applications for contract management, HR, procurement, administrative procedures, or customer onboarding.
  • Stronger trust: A qualified trust service provider (TSP) ensures that digital communication and electronic documents are based on a verified trust infrastructure.

For decision-makers, this means: Trust services are not just a compliance issue. They are an enabler for scalable, secure, and user-friendly digitalization – especially where signatures, seals, identity verification, or evidence-based delivery were previously paper-based.

Qualified Trust Services and TSPs

A qualified trust service meets the highest requirements of the eIDAS Regulation. It is provided by a qualified trust service provider (QTSP). In this context, the abbreviation TSP (trust service provider) is also commonly used.

A TSP must demonstrate technical, organizational, and legal compliance. This includes requirements for security, availability, identity verification, key management, and traceability. Qualified trust service providers are subject to regular audits and are supervised by a competent authority.

In Germany, the Federal Network Agency plays a central role as the supervisory authority for trust service providers. Additional technical guidelines, standards, and requirements for security and information technology—such as those from the BSI—are also relevant. The national Trust Services Act specifies certain aspects of the European regulation.

In Switzerland, this role is fulfilled by the Federal Office of Communications (BAKOM). Qualified trust service providers under ZertES must meet strict requirements, including regular audits by accredited bodies and registration in the Swiss provider directory.

The Role of Certification Authorities and Trust Lists

Certification authorities issue certificates and verify the identity of applicants beforehand. These certificates form the technical and legal basis for trusting signatures, seals, or website authentication.

Whether a trust service provider is qualified can be checked via the European Trusted List. Each EU member state maintains such a list, which includes qualified providers and services with their respective qualification status.

In Switzerland, verification is carried out via the BAKOM provider directory, which lists qualified certification service providers under ZertES. Businesses and public authorities can use this directory to check the recognition and status of Swiss trust service providers.

For businesses and public authorities, this verification is crucial: Only if the respective TSP is qualified for the specific service can the desired legal effect and security be reliably achieved.

Application in Public Administration and Businesses

In public administration, trust services are used wherever paper-based processes are to be replaced by digital ones: for applications, notices, tenders, approvals, personnel files, or internal communication. Electronic seals can confirm that a document actually originates from a public authority. Timestamps further enhance security by providing verifiable proof of the time of creation, submission, or approval.

In Switzerland, trust services under ZertES are particularly relevant for official procedures, public tenders, land registry offices, and the healthcare sector. Electronic signatures and seals under ZertES enable, for example, the legally valid submission of tax returns, building applications, or medical documents.

For businesses, this means: Trust services can be integrated into existing processes—such as contract management, procurement, HR, compliance, operations, or customer onboarding. Key factors include interfaces, role models, identification procedures, archiving, signature verification, and integration into specialist applications.

A typical application is digital contract signing: The identity of the signatory is verified, the document is electronically signed, a timestamp secures the time, and subsequent verification ensures that the content has not been altered. This creates digital processes that are user-friendly, efficient, and legally secure.

Trust services also play an important role in the Digital Product Passport (DPP): A qualified electronic seal can help businesses assign product data, registrations, and regulatory evidence to an organization in a trustworthy manner and ensure their integrity.

Why Security is Central to Trust Services

Trust services are more than just technical aids. They form a trust infrastructure on which business-critical and official processes are built. Security here means not only encryption or access control. It also involves reliable identities, tamper-proof documents, verifiable certificates, and traceable transactions.

In Switzerland, the requirements of ZertES, the Code of Obligations (CO), and sector-specific regulations (e.g., in finance or healthcare) must also be considered. Choosing a qualified provider under ZertES ensures that digital processes in Switzerland are legally secure and compliant.

For CISOs, compliance officers, and management, it is therefore crucial which TSP is used, how the application is integrated into existing systems, and whether the requirements of eIDAS, internal policies, and sector-specific regulations are met.

Frequently Asked Questions About Trust Services

What is the eIDAS Regulation?

The eIDAS Regulation is an EU law that governs electronic identification and trust services in the European single market. Its goal is to create a uniform legal framework for secure digital transactions.

What is ZertES?

ZertES is the Swiss Federal Act on Certification Services in the Field of Electronic Signatures. It regulates the requirements for electronic signatures, seals, timestamps, and certification service providers, ensuring that qualified electronic signatures (QES) are legally recognized in Switzerland and equivalent to handwritten signatures. ZertES thus provides the foundation for secure, legally valid digital transactions in Switzerland.

What is a Qualified Trust Service Provider?

A qualified trust service provider is a provider authorized to deliver qualified services under eIDAS. Such a TSP is subject to strict requirements, regular audits, and governmental supervision.

What is a Certification Service Provider?

A certification service provider (CSP) is a natural or legal person that issues, manages, and verifies digital certificates. In Switzerland, CSPs under ZertES must meet specific technical, organizational, and legal requirements to issue qualified certificates for electronic signatures, seals, or timestamps. CSPs are responsible for the security and trustworthiness of digital identities and documents and are supervised in Switzerland by the Federal Office of Communications (BAKOM).

Are Electronic Signatures Always Qualified?

No. There are simple, advanced, and qualified electronic signatures. Only the QES is legally equivalent to a handwritten signature in many cases.

Where Can You Check Qualified Providers?

Qualified trust service providers under eIDAS can be checked via the European Trusted List. In Switzerland, verification is carried out via the BAKOM provider directory, which lists qualified certification service providers under ZertES.

Why Are Timestamps Important?

Timestamps prove that certain data or documents existed at a specific point in time and have not been altered since. This strengthens integrity, security, and verifiability.

What Are Certification Services?

Certification services include the issuance, management, and verification of digital certificates. They enable electronic signatures, seals, and other trust services to be uniquely assigned to a person, organization, or technical identity.

Conclusion

Trust services are a vital component of modern digital infrastructure. They build trust in identities, documents, communication, and transactions—making digital processes in businesses and public administration robust, efficient, and compliant with eIDAS or ZertES.

The key is appropriate application: Not every process requires the same trust service, the same signature level, or the same TSP. By considering security, user-friendliness, and regulatory requirements together, you create a solid foundation for digital transformation.

SIGN8 supports organizations in the field of trust infrastructure, digital identities, electronic signatures, seals, and EUDI wallet readiness, helping to translate regulatory requirements into secure and user-friendly processes.